Kernel memory corruption via alarms_store off-by-one copy
Published Feb 4, 2026 · Updated Feb 4, 2026
Heap buffer overflow in the Linux Kernel w1_therm driver allows local users with high privileges to corrupt kernel memory via alarms sysfs writes. alarms_store allocates size bytes for a sysfs buffer whose NUL terminator is at index size, then strcpy copies that terminator one byte past the heap allocation. Reachability requires a loaded w1_therm driver, a supported 1-Wire temperature sensor exposing alarms, and high-privilege local write access; no specific service-failure mode is published.
Summary
What happened
Heap buffer overflow in the Linux Kernel w1_therm driver allows local users with high privileges to corrupt kernel memory via alarms sysfs writes. alarms_store allocates size bytes for a sysfs buffer whose NUL terminator is at index size, then strcpy copies that terminator one byte past the heap allocation. Reachability requires a loaded w1_therm driver, a supported 1-Wire temperature sensor exposing alarms, and high-privilege local write access; no specific service-failure mode is published.
The record
- CVE
- CVE-2025-71197
- Published
- Feb 4, 2026
- Updated
- Feb 4, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux Kernel
- Classifications
- T1499.004
- Attack vector
- local
- Privileges
- admin
Timeline
How it unfolded
- Feb 4, 2026CVE publishedPublication date reported by the CVE source.
- Feb 4, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=5.8
- Affected versionversion=e2c94d6f572079511945e64537eb1218643f2e68 <6a5820ecfa5a76c3d3e154802c8c15f391ef442e
- Affected versionversion=e2c94d6f572079511945e64537eb1218643f2e68 <6fd6d2a8e41b7f544a4d26cbd60bedf9c67893a0
- Affected versionversion=e2c94d6f572079511945e64537eb1218643f2e68 <761fcf46a1bd797bd32d23f3ea0141ffd437668a
- Affected versionversion=e2c94d6f572079511945e64537eb1218643f2e68 <e6b2609af21b5cccc9559339591b8a2cbf884169
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo